Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

Kazu

Also known asKazu

Kazu is a cybercrime and digital extortion threat actor described as a relative newcomer among cybercrime gangs, with activity referenced from spring 2025 and accelerated data-dump/extortion activity in June-July 2025. Available reporting characterizes Kazu as focused on data-theft extortion rather than ransomware encryption, and as likely targeting internet-facing web portals and web-enabled services. There is no solid evidence in the provided content that Kazu is a rebrand, splinter, or affiliate of another known extortion group, and it is unclear whether Kazu is a single individual or a group. The actor has claimed victims across government, military, and healthcare sectors. Reporting in the provided content states that most of Kazu's nearly three dozen listed victims were in Southeast Asia, the Middle East, and South America, with countries mentioned including Argentina, Bolivia, Colombia, Costa Rica, Iran, Mauritania, Mexico, Nepal, Saudi Arabia, Sri Lanka, Thailand, and Venezuela. Doctor Alliance was described as the only listed U.S. victim and the incident was characterized as Kazu's apparent first attack in North America. Kazu has been linked in the content to major healthcare-related extortion incidents. In the ManageMyHealth/Manage My Health breach in New Zealand, Kazu claimed responsibility for unauthorized access to a document storage module, claimed theft of more than 400,000 health documents / more than 428,000 files, published samples online, and demanded approximately US$60,000 while threatening public release or sale of the data. Reporting states Kazu later removed the listing and sample data from Telegram and a dark web leak site, but no public confirmation of payment was provided. In the Doctor Alliance incident, Kazu claimed theft initially of 353 GB / 1.24 million files, demanded US$200,000, and later claimed a second compromise that increased the alleged haul to nearly 1.27 TB / about 5 million files and raised the demand to US$500,000. Kazu told DataBreaches that an older unpatched vulnerability was exploited and that the same vulnerability was used again in the second intrusion; those specific intrusion details are claims by the actor and were not independently verified in the content. Observed tradecraft in the provided content includes claiming intrusions on underground forums, Telegram, dark web leak sites, and clearnet forums; exfiltrating large volumes of sensitive data; publishing sample files to substantiate claims; setting ransom deadlines; threatening to leak or sell stolen data; and operating extortion sites listing multiple victims. The content also notes Kazu-associated leaks involving sensitive personal, medical, and protected health information. One report states Kazu said the group was not politically motivated and was acting for financial gain and reputation building.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Health Care Equipment & Services

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇨🇴 Colombia
MITRE ATT&CK

Tradecraft

8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics12 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078×2
Valid Accounts
T1190×3
Exploit Public-Facing Application
TA0003
Persistence
1 technique
T1078×2
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×2
Valid Accounts
TA0005
Stealth
1 technique
T1078×2
Valid Accounts
TA0010
Exfiltration
4 techniques
T1020×4
Automated Exfiltration
T1041×3
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
2 techniques
T1486×4
Data Encrypted for Impact
T1657×2
Financial Theft
ACTIVITY FEED

Recent activity

13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping8

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.